Splunk Search

How do I find out how many times an offensive search ran in the past day/week?

ddrillic
Ultra Champion

We have, what we believe to be an offensive search. How can we find out how many times it ran recently and by whom?

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Is it a saved search or adhoc search?? If saved search, look at index=_internal sourcetypes=scheduler savedsearch_name=YourSearchName. For adhoc searches, check index=_audit.

View solution in original post

somesoni2
Revered Legend

Is it a saved search or adhoc search?? If saved search, look at index=_internal sourcetypes=scheduler savedsearch_name=YourSearchName. For adhoc searches, check index=_audit.

ddrillic
Ultra Champion

Gorgeous !!!

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...